Jump to content

Recommended Posts

Posted (edited)

Managed switch that you can interrogate the MAC address table on and locate the MAC address to a port.

 

Or trace it from switch to switch if need be.

 

Depends what switches you have how easy this is. We use iMC at the moment or do it the old fashioned way of going from switch to switch and we have 700+ switches, but we an normally track it down.

Edited by Davit2005
Posted (edited)

That is a bad idea™. You'd have to keep a database of authorised MAC addresses, keep it up to date and contend with the fact that it's trivial to spoof a MAC Address. Plus, a lot of devices now allow you to change your MAC Address on their wireless cards to limit tracking. This isn't worth the headache.

 

If you want to limit connections to your network to known and authorised devices, you're MUCH better off using 802.1x authentication, similar to WPAx Enterprise networks on your wireless systems. You'd have a certificate on your devices to verify their authenticity. That cert would be issued from an Enterprise CA via an MDM or by GPO. You'd have a RADIUS Server on your network to authenticate them and you'd need a switch that supports 802.1x. Can't speak for other manufacturers, but with Aruba at least, you'd need a L3 switch.

Edited by Norphy
  • Thanks 2
Posted
Might be helpful if we had the context of the question from the OP. Is this to deal with a ongoing issue or for future posibilities but yes 802.1x would be the ultimate choice as everything else has a possibility of counteracted i.e. MAC spoofing etc.
Posted
Process document that we are being audited on said that we will be alerted to unauthorized MAC addresses. We have web managed HP Procurve 1800-24G not sure if they can do what we are talking about.
Posted
Process document that we are being audited on said that we will be alerted to unauthorized MAC addresses.

Sounds like BS boxtickery to me. If you can't do it you could use that as an opportunity to get the funding to upgrade your network :p

It sounds like it's going to be a lot of work for very little gain.

Posted
Process document that we are being audited on said that we will be alerted to unauthorized MAC addresses.

 

I would argue that it’s too late at this point. Unauthorised devices shouldn’t be getting anywhere.

 

It’s a bit like having CCTV monitoring a unlocked door.

Posted
Process document that we are being audited on said that we will be alerted to unauthorized MAC addresses. We have web managed HP Procurve 1800-24G not sure if they can do what we are talking about.
A valuable lesson for the rest of us - unfortunately too late for you.

 

I have fought against statements in process documents before on the basis that while it's a nice aspiration and not necessarily a bad idea, if there no realistic chance of achieving it, it can only go badly.

 

Check your process documents and if they have something in then you know you can't do, get them changed and authorised by governors.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...